PluginProbe
Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More / 6.2.1
Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More v6.2.1
6.35 6.34 6.33.1 6.33 6.32.1 6.32 6.31 6.25 6.25.1 6.26 6.26.1 6.27 6.28 6.29 6.3 6.3.1 6.3.2 6.30 6.4 6.4.1 6.4.2 6.5 6.5.1 6.5.2 6.5.3 All 141 releases
← All changes | classes/views/shared/errors.php +3 -15 6.276.2.1 View file →
@@ -5,9 +5,9 @@
5 5
6 6 if ( isset( $message ) && '' !== $message ) {
7 7 if ( FrmAppHelper::is_admin() ) {
8 8 echo '<div class="frm_updated_message">';
9 - FrmAppHelper::kses_echo( $message, 'all' );
9 + echo FrmAppHelper::kses( $message, 'all' ); // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
10 10 echo '</div>';
11 11 } else {
12 12 echo FrmAppHelper::maybe_kses( $message ); // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
13 13 }
@@ -15,34 +15,22 @@
15 15
16 16 if ( ! isset( $show_messages ) ) {
17 17 $show_messages = array();
18 18 }
19 -
20 19 $show_messages = apply_filters( 'frm_message_list', $show_messages );
21 -
22 20 if ( is_array( $show_messages ) && count( $show_messages ) > 0 ) {
23 - // Define a callback function to add 'data-action' attribute to allowed HTML tags
24 - $add_data_action_callback = function ( $allowed_html ) {
25 - $allowed_html['span']['data-action'] = true;
26 - return $allowed_html;
27 - };
28 21 ?>
29 22 <div class="frm_warning_style" role="alert">
30 23 <ul id="frm_messages">
31 24 <?php
32 - // Add the callback function to the 'frm_striphtml_allowed_tags' filter
33 - add_filter( 'frm_striphtml_allowed_tags', $add_data_action_callback );
34 -
35 25 foreach ( $show_messages as $m ) {
36 - echo '<li>' . FrmAppHelper::kses( $m, array( 'a', 'br', 'span', 'p', 'svg', 'use' ) ) . '</li>'; // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
26 + echo '<li>' . FrmAppHelper::kses( $m, array( 'a', 'br', 'span', 'p' ) ) . '</li>'; // phpcs:ignore WordPress.Security.EscapeOutput.OutputNotEscaped
37 27 }
38 - // Remove the callback function from the 'frm_striphtml_allowed_tags' filter
39 - remove_filter( 'frm_striphtml_allowed_tags', $add_data_action_callback );
40 28 ?>
41 29 </ul>
42 30 </div>
43 31 <?php
44 -}//end if
32 +}
45 33
46 34 if ( ! empty( $warnings ) && is_array( $warnings ) ) {
47 35 ?>
48 36 <div class="frm_warning_style inline" role="alert">